CVE Database /
CVE-2025-12965
CVE · Medium
CVE-2025-12965 — Magical Posts Display – Elementor Advanced Posts widgets [magical-posts-display] < 1.2.55
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-12965
|
Magical Posts Display – Elementor Advanced Posts widgets [magical-posts-display] < 1.2.55 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 1.2.55
|
1.2.55 |
2025-12-11 |
—
|
CVE-2025-12965
A vulnerability exists in the Magical Posts Display plugin for WordPress, specifically in the Magical Posts Accordion widget, where user-supplied input is not properly sanitized or escaped, allowing an authenticated attacker with Author-level access or higher to inject malicious HTML code that will be executed when accessed by another user. This enables the attacker to inject arbitrary web scripts, which can then be executed by users visiting the affected page.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings